Episode Description
Open source is already in your stack, whether you deliberately installed it or not. In this ChannelCon 2026 talk, Jared lays out a practical way for MSPs to decide what deserves trust, what needs guardrails, and what needs to go.
Takeaways:
• Scope the risk by asking what the software touches and what happens if it breaks
• Check whether the project is actually alive, maintained, and prepared to handle security reports
• Look beyond the package itself to dependencies, SBOMs, and supply-chain risk
• Assign one clear owner to monitor approved software after the initial review
And one important reality check: commercial software is not automatically safer. Your vendors are using open source too.
Make sure to follow the podcast or ask your own questions at:
https://blacksmithinfosec.com/nisty/
Want to see the slides or get the extra content? That's all available at https://blacksmithinfosec.com/channelcon